Institutional Crypto Custody: How Digital Assets Are Stored and Secured

Cryptocurrencies are gradually becoming part of the traditional financial infrastructure. According to data from the Basel Committee on Banking Supervision, cryptoassets held in custody by the world’s largest banks reached about $23 billion by mid-2024. Meanwhile, data from PwC Switzerland showed that 60% of banks offered crypto-related services to clients in 2025, with digital asset custody and trading among the key areas for further development.
Institutional crypto custody, however, involves more than choosing a wallet or an exchange. It’s a comprehensive system of technologies and procedures. Financial institutions need to segregate access to assets, control transactions, maintain records, keep client funds separate, and comply with regulatory requirements.
Institutional Crypto Custody Models
For a financial institution, crypto custody starts with deciding who will be responsible for access to the assets and their safekeeping. In practice, there are 3 main models.
Self-Custody
Under the self-custody model, a financial institution manages the cryptographic keys and infrastructure used to access digital assets. It also sets security policies, transaction procedures, and employee permissions.
The main advantage of this model is full control over the assets and their security. With that control, however, the institution also assumes the associated custody risks. It needs to ensure:
- Protection of cryptographic keys
- Access backup and recovery
- Segregation of employee permissions
- Transaction controls and approvals
- Protection of infrastructure against cyberattacks
- Uninterrupted system operation
Self-custody doesn’t mean that a bank has to develop the entire technology infrastructure in-house. It can use solutions from external providers while retaining control over the keys and asset management.
Zürcher Kantonalbank (ZKB), for example, uses this model. In 2024, the bank launched a BTC and ETH trading and custody service for retail clients through its online banking platform and mobile app. The bank holds client assets itself rather than outsourcing custody to third-party providers.
Third-Party Custody
Another option is to outsource custody to a specialized provider. The financial institution uses the custodian’s existing infrastructure and delegates some functions related to key security and transaction processing.
When selecting a custodian, the institution needs to consider:
- Reliability and financial stability
- Key protection technologies
- Procedures for granting and restricting access
- Disaster recovery procedures
- Allocation of responsibilities between the parties
- Regulatory compliance
The use of third-party providers is permitted, for example, in the U.S. The Office of the Comptroller of the Currency (OCC) allowed national trust banks to provide digital asset custody services and use third-party providers for these activities. The bank, however, remains responsible for assessing risks and overseeing the provider’s operations.
Hybrid Model
The hybrid model combines self-custody with solutions provided by external vendors. The financial institution retains control over key processes while outsourcing some technology or operational functions to a third-party provider.
Banco Bilbao Vizcaya Argentaria (BBVA), for example, uses this approach. In 2025, the bank launched a crypto service for retail clients in Spain. FinTech company Ripple provides the technology infrastructure for digital asset custody within the service, while BBVA retains control over private keys and their use.
The choice of custody model depends on which functions the institution is prepared to handle internally and which it is willing to outsource to external providers.
Institutional Digital Asset Custody Architecture
After selecting a custody model, a financial institution needs to determine how access to the assets will be structured. Based on asset availability and the degree of infrastructure isolation, there are 3 custody tiers:
- Hot storage. The infrastructure used to process transactions is connected to the network continuously or regularly, making assets available almost immediately. This tier is suitable for client settlements, transfers, trading, and liquidity management. Because it is more exposed to external attacks, the amount of funds held in hot storage is typically limited.
- Warm storage. This is an intermediate tier where access to assets is restricted by additional procedures, but the infrastructure isn’t fully isolated from the network. These funds aren’t used for daily operations but can be accessed when needed.
- Cold storage. The keys or infrastructure used to sign transactions are isolated from the network. This reduces the risk of remote attacks but makes access to assets more complex and time-consuming. Cold storage is therefore suitable for funds that aren’t needed for ongoing operations.
In practice, institutions use these tiers simultaneously. Funds needed for ongoing operations are kept in a more accessible environment, while the remaining assets are isolated. This allows institutions to maintain the required liquidity while reducing the amount of funds exposed to a potential attack.
Security, however, depends not only on the custody tier but also on how keys are protected and the rules governing transactions.
Digital Asset Security and Access Controls
Financial institutions need to protect cryptographic keys and determine who can control assets and under what conditions. They use several technologies and control mechanisms for this purpose.
- Hardware security modules (HSMs) are used to generate, store, and use cryptographic keys in a secure environment. They can perform signing operations, restrict access, and log actions involving keys.
- Multisignature distributes control over assets across multiple keys. A transaction requires multiple signatures. For example, a 2-of-3 scheme allows a transaction to be executed only when 2 of 3 signatures are provided. This helps separate responsibilities and prevents assets from being controlled with a single key.
- Multi-party computation (MPC) distributes the signature generation process across multiple participants or devices without requiring the full private key to be stored in a single location.
Technology safeguards are supplemented by transaction rules. These determine:
- Who can initiate and approve transactions
- What amounts are permitted
- Which addresses funds can be sent to
- When additional approval is required
- Under what conditions a transaction must be blocked
For example, a large transfer may require approval from several employees, while a transaction to a new address may be subject to additional checks.
Regulation, Recordkeeping, and Asset Controls
Technical safeguards alone aren’t sufficient for institutional digital asset custody. Financial institutions also need to comply with regulatory requirements and be able to determine at any time where assets are held, who owns them, and who is authorized to control them.
Specific rules vary by jurisdiction, but the main requirements include:
- Protection of cryptographic keys and access controls
- Recordkeeping for each client’s assets
- Reconciliation of internal records with actual asset holdings
- Segregation of client funds from the institution’s own funds
- Protection of client assets in the event of insolvency
- Access recovery and business continuity
Approaches to implementing these requirements vary by jurisdiction:
- European Union. The MiCA regulation requires client cryptoassets to be segregated from the service provider’s own assets and a register of each client’s positions to be maintained. If the provider becomes insolvent, client assets must be protected from claims by its creditors. Custody providers must also have policies and procedures in place to safeguard assets and the means of access to them.
- Dubai. VARA rules set requirements for recordkeeping, reconciliation, and segregation of client assets. A separate wallet must be maintained for each client, and custodians are prohibited from using assets held in custody for their own purposes. Separate requirements apply to key management, access controls, and business continuity.
- South Korea. Virtual asset service providers must keep at least 80% of the value of client assets in cold wallets and segregate them from their own funds. They must also maintain insurance or reserves to cover hacking, technical failures, and other incidents.
- Japan. At least 95% of client cryptoassets must be held in cold storage. The remaining assets are subject to additional safeguards, and client assets must be accounted for separately from the service provider’s own assets.
- The U.S. Banking regulators don’t set a single mandatory percentage of assets that must be held in cold storage. Instead, they focus on risk management. Banks need to control access to keys, maintain cybersecurity and internal controls, establish disaster recovery procedures, and assess risks when working with third-party providers.
- The U.K. The FCA’s new regime includes requirements for safeguarding client cryptoassets, recordkeeping and reconciliation, and private key management. The new rules will take effect under the cryptoasset regulatory regime in 2027.
Working with external providers requires particular attention. A bank can outsource certain functions to a specialized platform, custodian, or sub-custodian, but it remains responsible for managing the associated custody risks. The institution needs to define each party’s functions and responsibilities in advance, establish procedures for overseeing the provider, and determine what steps to take in the event of a disruption or termination of the relationship.
Institutional crypto custody is becoming part of the financial infrastructure, but there is no universal approach. Banks and investment firms choose a model based on the scale of their operations, regulatory requirements, and their own technical capabilities.
